Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.400exploits catalogados
37.193CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.340VulnCheck XDB 9001Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
CA eSCC r8/1.0 / eTrust Audit r8/1.5 - Arbitrary File Manipulation
Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BandSite CMS 1.1 - 'login_header.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Grayscale BandSite CMS allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updateuser?in_name' Servlet Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'addrlist' Servlet Multiple SQL Injections
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updatemail' Servlet Arbitrary Mail Message Manipulation
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'updateuser?in_id' Servlet Arbitrary User Information Modification
The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'downloadfile' Servlet Traversal Arbitrary File Access
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NeoSys Neon Webmail for Java 5.06/5.07 - 'maillist' Servlet Multiple SQL Injections
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dr.Web AntiVirus 4.33 - LHA long Directory name Local Overflow
Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote att
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ESyndiCat 1.5 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedBLoG 0.5 - '/admin/config.php?root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Innovate Portal 2.0 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedBLoG 0.5 - 'imgen.php?Root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedBLoG 0.5 - '/admin/index.php?root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedBLoG 0.5 - 'common.php?root_path' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EShoppingPro 1.0 - 'Search_Run.asp' SQL Injection
SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PT News 1.7.8 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NixieAffiliate 1.9 - 'lostpassword.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ECardPro 2.0 - 'search.asp' SQL Injection
SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to ex
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Charon Cart 3.0 - 'Review.asp' SQL Injection
SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DotNetNuke 4.0 - HTML Injection
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zix Forum 1.12 - 'RepId' SQL Injection (2)
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hitweb 3.0 - 'REP_CLASS' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-post Web Forum 0.x.1.0 - 'profile.php' Multiple SQL Injections
Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/inst
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-post Web Forum 0.x.1.0 - 'pm.php?replyuser' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.x - 'db_operations.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jupiter CMS 1.1.4/1.1.5 - modules/register Multiple SQL Injections
Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.x - Multiple Script Array Handling Full Path Disclosures
PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/chec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jupiter CMS 1.1.4/1.1.5 - 'galleryuploadfunction.php' Arbitrary File Upload
Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to up
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.